Offline multi-factor one-time password authentication
Abstract
A server may encrypt an authentication signal using a public encryption key (e.g., a public encryption key that was generated together with a private encryption key stored on a user device pre-registered with the server). The server passes the encrypted authentication signal to a user agent (e.g., such as the web browser) and the user agent encodes the encrypted authentication signal into a machine-readable optical label. The user agent displays the machine-readable optical label for scanning by the user device. Accordingly, the user device may be unlocked by a user (e.g., using an unlock password or an unlock gesture), and the user device may scan the machine-readable optical label, decode the encrypted authentication signal encoded in the machine-readable optical label, decrypt the decoded authentication signal that was encrypted by the server, and generate an authentication code based on the decrypted authentication signal.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for user authentication, comprising:
receiving an authentication signal, wherein the authentication signal is encrypted using a public encryption key and encoded as a machine-readable optical label; decrypting the authentication signal using a private encryption key, wherein the private encryption key is generated together with the public key and stored in a hardware security module of an electronic device; and generating an authentication code based on the decrypted authentication signal.
2 . The method of claim 1 , further comprising:
receiving user input initiating an offline authentication mode, wherein the authentication signal is received according to the offline authentication mode.
3 . The method of claim 1 , further comprising:
determining that an unlocking process has been completed for the electronic device containing the hardware security module, wherein the authentication code is generated based on the determination.
4 . The method of claim 1 , further comprising:
accessing a camera of the electronic device; and capturing an image of the machine-readable optical label using the camera.
5 . The method of claim 1 , further comprising:
decoding the machine-readable optical label to obtain a digital representation of the authentication signal, wherein the authentication signal is decrypted based on the digital representation.
6 . The method of claim 1 , further comprising:
entering the authentication code into a code entry page displayed on an external device.
7 . The method of claim 1 , further comprising:
registering the electronic device for offline authentication, wherein the private encryption key and the public encryption key are generated based on the registration of the electronic device.
8 . The method of claim 1 , further comprising:
registering an additional device for offline authentication, wherein an additional private encryption key and an additional public encryption key are generated based on the registration of the additional device; receiving an additional authentication signal encrypted using the additional public encryption key; attempting to decrypt the additional authentication signal encrypted using the private encryption key stored in the local hardware security module of the electronic device; and determining that the additional authentication signal is invalid based on the attempted decryption.
9 . The method of claim 1 , wherein:
the machine-readable optical label comprises a Quick Response (QR) code.
10 . The method of claim 1 , wherein:
the authentication code comprises a one-time numerical code.
11 . A method for user authentication, comprising:
generating an authentication signal using a public encryption key; displaying a machine-readable optical label representing the authentication signal to the electronic device; receiving an authentication code from the electronic device in response to displaying the machine-readable optical label, wherein the authentication code is generated using a private encryption key generated together with the public key and stored in a local hardware security module of an electronic device; and authenticating a user based on the authentication code.
12 . The method of claim 11 , further comprising:
receiving user input initiating an offline authentication mode, wherein the authentication signal is generated according to the offline authentication mode.
13 . The method of claim 11 , further comprising:
displaying a code entry page, wherein the authentication code is received via the code entry page.
14 . The method of claim 11 , further comprising:
determining that the authentication code is valid, wherein the user is authenticated based on the determination.
15 . The method of claim 11 , further comprising:
registering the electronic device for offline authentication, wherein the private encryption key and the public encryption key are generated based on the registration of the electronic device.
16 . The method of claim 15 , further comprising:
registering an additional device for offline authentication, wherein an additional private encryption key and an additional public encryption key are generated based on the registration of the additional device; generating an additional authentication signal encrypted using the additional public encryption key; and displaying an additional machine-readable optical label representing the additional authentication signal to the electronic device.
17 . An apparatus for user authentication, comprising:
an offline authentication component configured to receive an authentication signal and to generate an authentication code based on the authentication signal, wherein the authentication signal is encrypted using a public key and encoded as a machine-readable optical label; and a hardware security module configured to decrypt the authentication signal using a private encryption key that is generated together with the public key.
18 . The apparatus of claim 17 , further comprising:
a camera configured to capture an image of the machine-readable optical label.
19 . The apparatus of claim 17 , wherein:
the machine-readable optical label comprises a Quick Response (QR) code.
20 . The apparatus of claim 17 , wherein:
the offline authentication component is further configured to receive user input initiating an offline authentication mode, wherein the authentication signal is received according to the offline authentication mode.Join the waitlist — get patent alerts
Track US2022138306A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.